Refine By
Clear all filter
About 91501 results for "*"
PRACTICE NOTES
In brief Data protection laws in the EEA (the EU plus Iceland, Norway, and Liechtenstein) seek to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, data protection laws impose a large number of obligations on those ‘processing’ personal data (and on the controllers of such processing). The data protection regime expressly recognises that the processing of children’s personal data requires specific protection, and provides enhanced protection for children’s personal data. This is because children may be less aware of the risks, consequences and safeguards concerned, and their rights in relation to the processing of personal data. Those additional protections are also relevant to organisations which aren’t actively seeking to process children’s personal data (eg designing a service aimed at adults) since they will need to consider whether they may inadvertently end up processing children’s personal data (eg if a child accesses that service). Organisations that do not adequately protect children’s data protection rights and privacy face particular scrutiny. For examples of enforcement
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module four (processor to controller) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A,
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module one (controller to controller) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A the data exporter is a controller and the data importer is a controller,
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module three (processor to processor) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A, the data exporter is a processor and the data importer is a processor, and the name, address, contact person’s details and relevant activities for each of them is as set out in [insert where set
PRECEDENTS
1 In this [clause], 2021 EU SCCs means module two (controller to processor) of the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914. The [Importer Party] shall comply with the data importer’s obligations, and the [Exporter Party] shall comply with the data exporter’s obligations, set out in the 2021 EU SCCs, which are hereby incorporated into and form part of this Agreement. In such incorporated 2021 EU SCCs: 1.1 for the purposes of Annex I.A the data exporter is a controller and the data importer is a processor, and the name, address, contact person’s details and relevant activities for each of them is as set out in [insert where set
PRACTICE NOTES
This Practice Note tracks key developments in relation to the European Commission’s reforms to the procedure for enforcement of the EU’s General Data Protection Regulation (EU) 2016/679 (EU GDPR) in cross-border cases. The reform takes place via Regulation (EU) 2025/2518 (the Procedural Regulation). This tracker summarises legislative and regulatory developments in addition to letters, opinions, responses, recommendations and advice issued by EU institutions, bodies, associations, offices and agencies. Note that the Procedural Regulation (reform to procedure in cross-border cases) is separate from the proposals for simplification of record-keeping rules and other ‘Digital Omnibus’ package changes to the EU GDPR—for more on that score, see instead Practice Notes: EU 2024–2029 simplification agenda—tracker and EU Digital Omnibus—tracker. Background to the proposal for EU GDPR procedural rules Under the EU GDPR, independent national data protection authorities, also known as supervisory authorities (SAs), have been tasked with its enforcement and are expected to co-operate and adopt shared decisions under the ‘one-stop-shop’ mechanism. Ultimately, this ‘one-stop-shop’ mechanism allows operators to deal with a single SA in cross-border data protection cases, while
PRACTICE NOTES
EU data protection laws include a right to data portability. That right allows individuals to obtain from a controller a copy of their personal data in a structured, machine-readable format. In addition, in some circumstances, individuals have the right to have that data transferred directly by the controller to another controller. This Practice Note addresses the right of data portability. It assumes a degree of knowledge about EU data protection laws. For a general introduction to those data protection laws, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Note that this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction. The right to data portability is designed to both support and enable the free flow of personal data within the EU, and to encourage healthy competition between controllers, by not only facilitating consumers switching between various service providers,
PRACTICE NOTES
This Practice Note tracks noteworthy decisions of the Court of Justice of the European Union related to data protection, including the interpretation of the General Data Protection Regulation (EU) 2016/679 (EU GDPR). The table below lists only final decisions, and may be read in parallel with Practice Note: EU data protection—horizon scanner—Cases before the Court of Justice of the European Union, for more information about the status of cases currently proceeding through the court. For an introduction to the EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Cases Case name and date Summary Jautiva, Case C-798/243 September 2026 Key themes: Public disclosure of shareholder data—lawfulness and proportionality—Articles 5 and 6The Court of Justice held that Article 14(d) of Directive (EU) 2017/1132 does not require the disclosure of information relating to all shareholders, including minority shareholders, of public limited liability companies. It further held that Articles 5 and 6 of the EU GDPR, read with Articles 7 and 8 of the Charter of Fundamental Rights of the European Union,
PRACTICE NOTES
This Practice Note covers the principles for handling personal data that form the core of the EU General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) applicable in the EEA (as explained further below). For a general introduction to EU data protection law, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). Note that this Practice Note considers provisions under the EU GDPR applicable in EEA states at the supranational level only—refer to guidance from the relevant national data protection authorities and national laws regarding the approach that may be taken in any EEA jurisdiction. The EU GDPR contains a set of core data protection principles that controllers must comply with. These are set out in Article 5, and include: • the lawfulness, fairness and transparency principle • the purpose limitation principle • the data minimisation principle • the accuracy principle • the storage limitation principle • the integrity and confidentiality principle • the accountability principle Recital 39 also offers additional guidance on each of the above. Lawfulness, fairness and transparency The first
PRACTICE NOTES
This Practice Note provides guidance for a party involved in a commercial transaction between businesses to help them determine whether they are an independent controller, joint controller or processor under the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR). For a general introduction to the EU GDPR, see Practice Note: The EU’s General Data Protection Regulation (EU GDPR). In brief Data protection law in the EEA (the EU plus Iceland, Norway, and Liechtenstein) is intended to ensure information about living individuals (within the definition of ‘personal data’) is used fairly and responsibly. To help ensure that, the EEA data protection laws impose a large number of obligations on those ‘processing’ personal data (and on those who control such processing) and grant rights to those whose personal data is processed (the ‘data subjects’). In summary, ‘processing’ includes doing almost anything with personal data, including storing, sharing, deleting or using it. It is vital that natural persons and organisations involved
PRACTICE NOTES
In summary, organisations with an establishment in the EEA that process personal data and that cannot rely on an exception under the General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) will be within the scope of the EU GDPR. Those organisations without a physical presence in the EEA but that process personal data, whether regularly or sporadically, should consider whether they are likely to be caught by the EU GDPR and/or required to appoint a representative in the EEA. This Practice Note covers: • Key guidance • Territorial scope under the Data Protection Directive • Territorial scope under the EU GDPR • Extra-territorial enforceability of the EU GDPR • Complying with the EU GDPR • Appointing a representative in the EEA • Exceptions • Equivalent provisions under the UK GDPR Although the text of the EU GDPR refers throughout to the ‘Union’, it is stated on page one of the EU GDPR that it is a text ‘with EEA relevance’, meaning all provisions are intended to be applicable in respect of all EEA
PRACTICE NOTES
This Practice Note is a guide explaining ‘how to’ incorporate precedent controller to processor (C2P) or processor to processor (P2P) provisions for compliance with the EU’s General Data Protection Regulation, Regulation (EU) 2016/679 (EU GDPR) into a commercial contract. It is written from a supranational perspective and the laws of applicable EEA Member States and other jurisdictions should be sought where appropriate in the context of the applicable law of the contract and the location of performance of obligations in connection with the contract. This ‘how to’ guide assumes a basic level of knowledge about data protection law, including the meaning of key terms such as ‘personal data’ and ‘processing’. For introductory information on data protection law, see Practice Notes: Key definitions under EU data protection law and The EU’s General Data Protection Regulation (EU GDPR). This guide does not address: • the drafting and negotiation of mandatory C2P/P2P provisions in and of themselves • data sharing arrangements between controllers (C2C). For further guidance on such arrangements, see Practice